Lead Security Engineer

Thomson Reuters

Frisco (TX)

Hybrid

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Thomson Reuters is seeking a Lead Security Engineer to set technical direction for securing its global infrastructure. This senior IC role covers application, cloud, and on‑premises estate with a focus on building security controls and processes across patching, image refreshes, and guardrails.

You will mentor engineers, collaborate with Information Security, Platform Engineering, and application teams, and drive AI-augmented tooling adoption while balancing risk and impact.

Qualifications

  • 8+ years hands-on experience in security engineering or cloud/infrastructure security with senior technical direction responsibilities.
  • Deep understanding of security principles across application, cloud, and infrastructure layers.
  • Working command of vulnerability management at scale: prioritization, CVSS/EPSS, KEV, SLA-driven burndown.

Responsibilities

  • Act as the technical lead for security across application, cloud, and infrastructure; own security backlog and escalation.
  • Design and build security controls across OS, container orchestration, CI/CD, cloud config, and network boundaries.
  • Design new security processes, patching cycles, and image refreshes to balance speed and safety.
  • Propose improvements, turn them into standards, and mentor engineers; coordinate with regional security teams.
  • Own reporting and metrics; build runbooks, standards, and escalation paths for auditable security capability.

Skills

Security engineering
Vulnerability management
Cloud security
Multi-cloud experience
Automation tooling
SAST
SCA

Education

Bachelor's degree in CS or Information Security

Tools

SAST
SCA

Job description

The Opportunity

Do you want to set the technical direction for how a global business secures its infrastructure at scale? Thomson Reuters™ is investing in a dedicated security engineering capability, and we are looking for a hands‑on technical lead to help build and shape it. You will design how we secure our estate end to end, not just work through a backlog. This role sits on our Service Management & Transformation team.

As the Lead Security Engineer, you will be the technical lead for security across our application, cloud, and infrastructure estate, which spans on‑premises data centers and major clouds. This is a senior individual‑contributor role: you set the technical direction and guide the work of the engineers around you, but you are not their line manager. It is as much a process‑design role as a hands‑on one. You will design new security controls and ways of working across patching, hardening, network isolation, identity, and secrets management, revamping patching cycles and golden‑image refreshes so the team can move fast without sacrificing safety, and you will partner across Information Security, Platform Engineering, and application teams to raise our overall security posture.

About the Role

In this opportunity as Lead Security Engineer, you will:

  • Act as the technical lead for security across application, cloud, and infrastructure. Set technical direction, make the key calls, own the shape and quality of the security backlog end to end, and serve as the point of escalation for complex security and remediation work, without direct line‑management responsibility.
  • Design and build security controls across layers such as operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries, to defend against sophisticated adversaries and insider threats.
  • Design new security processes and ways of working, revamping patching cycles and golden‑image and base‑image refreshes across cloud and on‑prem, so the team can move fast without sacrificing safety.
  • Come to the table with ideas: identify where security and remediation processes can be improved, propose better approaches, and turn them into standards the team adopts.
  • Set the technical approach across the full security scope: application and open‑source dependency fixes, infrastructure patching, cloud configuration and guardrails, WAF, network isolation, and secrets and machine‑identity management. Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA‑driven burndown), and champion adoption of AI‑augmented security tooling, including SAST and SCA.
  • Raise the technical bar by reviewing fixes and mentoring engineers, and coordinate with the wider security team across regions to keep standards and priorities aligned across time zones.
  • Own clear reporting and metrics, and build the runbooks, standards, and escalation paths that make security a repeatable, auditable capability.
About You

You're a fit for the role of Lead Security Engineer if your background includes:

  • 8+ years of hands‑on experience in security engineering, vulnerability management, or cloud and infrastructure security, including time as a technical lead or senior individual contributor setting direction and guiding the technical work of other engineers, plus a bachelor's degree in Computer Science , Information Security, or a related field (or equivalent practical experience).
  • A deep understanding of security principles, common vulnerabilities, and best practice across application, cloud, and infrastructure layers.
  • A working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA‑driven burndown.
  • Breadth across the security stack: application and dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity and access controls, with multi‑cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage) alongside on‑premises infrastructure.
  • A track record of designing and improving technical processes, such as patching cycles, image or GAMI refreshes, or remediation workflows, rather than only executing them, with a proactive mindset for identifying and closing security gaps through automation and tooling; experience with AI‑assisted or automated security tooling is an advantage.
  • Strong judgment on balancing risk reduction against operational and customer impact.
  • Excellent written and verbal communication, comfortable operating across security, engineering, and business audiences and able to convey complex security concepts to technical and non‑technical stakeholders, with enthusiasm for collaborating with cross‑functional teams to build secure, reliable systems that scale globally.

#LI-LB1

What's in it For You?

Hybrid Work Model: We've adopted a flexible hybrid working environment for our office‑based roles while delivering a seamless experience that is digitally and physi

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Thomson Reuters • Frisco (TX)

Hybrid
USD 140,000 - 210,000
Hybrid Work
Flexible policies
Career growth
+2
Security Engineer
Security Engineer

Thomson Reuters • Frisco (TX)

Hybrid
USD 110,000 - 160,000
Hybrid work model
Flex My Way
Two mental health days
+1
Lead Security Engineer — Hybrid, Global Security Leader
Lead Security Engineer — Hybrid, Global Security Leader

Thomson Reuters • Frisco (TX)

Hybrid
USD 140,000 - 190,000
Security Engineer
Security Engineer

Iceberg • Chicago (IL)

On-site
USD 120,000 - 170,000
Lead Security Engineer: Cloud, App & Infra Defender
Lead Security Engineer: Cloud, App & Infra Defender

Refinitiv • Frisco (TX), Northern (KY)

Hybrid
USD 118,000 - 220,000
Flexible vacation
Mental Health Days
Headspace access
+2
Global Security Architect & Tech Lead
Global Security Architect & Tech Lead

Socket.dev • Town of Texas (WI)

Hybrid
USD 118,000 - 220,000
Hybrid work model
Career growth
Competitive benefits
+1
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Lead Security Engineer – Cloud & App Security Architect
Lead Security Engineer – Cloud & App Security Architect

Relha LLC • Frisco (TX)

Hybrid
USD 118,000 - 220,000
Hybrid work model
Mental health days
Tuition reimbursement
+1
Cyber Security Engineer—Technical Lead
Cyber Security Engineer—Technical Lead

Leidos • Bethesda (MD)

On-site
USD 150,000 - 180,000
Hands-on Tech Lead (Hybrid/Boston)
Hands-on Tech Lead (Hybrid/Boston)

Roberts Recruiting, LLC • Boston (MA)

On-site
USD 120,000 - 150,000